Story perspectives
New Herodotus Trojan Targets Banks with Phishing Tactics
10/30/2025
1 of 1
Story summary
- ThreatFabric identifies a new Android banking Trojan named Herodotus.
- Herodotus mimics human typing by introducing randomized keystroke delays that simulate real user input.
- The malware is marketed as Malware-as-a-Service.
- It spreads mainly through phishing messages and sideloading.
- Active campaigns are observed in Italy and Brazil, targeting financial institutions and cryptocurrency platforms.
